Security & Data Handling
Last updated: September 23, 2026
How we get access to CitiSpan
You add us as our own user on your grant in CitiSpan, the same way you would add a staff member. You never share your password with us. Everything we do shows up in CitiSpan under that user, and you can remove it at any time, which stops our access immediately.
Where the service runs
The automation runs on Amazon Web Services in the United States, in a Nimbusworks account used only for this work. It runs as short scheduled jobs with no server that anyone can log in to and no open inbound connections. Stored data is encrypted, and all connections to CitiSpan and our other providers are encrypted.
Credentials
The CitiSpan login for your account is kept in an encrypted secret store, read only at the moment a job runs, and never written into a file, an email, or a report. Each customer's settings and credentials are kept separate.
Your data kept separate
Each customer's working data is kept in its own database, so one program's records are never mixed with another's, and deleting your data removes exactly your data.
What we do and don't decide
We enroll participants, file attendance, and correct records you tell us are wrong. We never decide consent for a child. Consent and release fields are recorded exactly as your program's forms or written instructions say. When something is missing, we flag it by name for your staff to resolve.
Data minimization
Attendance is filed by CitiSpan PersonID. Student names are not included in the attendance files we upload.
Every run is checked and logged
Each write is previewed before it is made and re-read from CitiSpan afterward. If the numbers don't match, the run is recorded as a failure, not a success, and we are alerted. Run logs are kept with timestamps so you can show a funder what was reported and when. A separate watchdog alerts us if scheduled runs stop.
Who can reach it
Administrative access to the service requires single sign-on with multi-factor authentication. Account activity is recorded in a tamper-evident audit log kept for a year. Code is only deployed from committed, version-controlled releases, each stamped with its version.
Your data, your control
We never sell or share your data. When you leave, we stop all runs, you remove our CitiSpan user, and we export your records on request and then delete them.
Service providers
We use a small set of providers to run the service: Amazon Web Services (hosting), Cloudflare (website and working database), and Google Workspace (email). They process data only as needed to run the service.
Responsible disclosure
Found a security issue? Email [email protected] and we'll respond promptly.